CVE-2016-6621: phpMyAdmin

High severity, CVSS 8.6. EPSS: 1.9% chance of exploitation in the next 30 days.

The setup script for phpMyAdmin before 4.0.10.19, 4.4.x before 4.4.15.10, and 4.6.x before 4.6.6 allows remote attackers to conduct server-side request forgery (SSRF) attacks via unspecified vectors.

Affected products

  • phpMyAdmin phpMyAdmin: up to and including 4.0.10.18; version 4.4.0 only; version 4.4.1 only; version 4.4.1.1 only; version 4.4.2 only; version 4.4.3 only; …

Published 2017-01-31. Last modified 2026-06-17.